RSS   Vulnerabilities for
'Metform elementor contact form builder'
   RSS

2022-05-10
 
CVE-2022-1442

CWE-862
 

 
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.

 

 >>> Vendor: Wpmet 2 Products
Elements kit elementor addons
Metform elementor contact form builder


Copyright 2024, cxsecurity.com

 

Back to Top